ATT&CKReferencesGitHub Pupy

GitHub Pupy

Nicolas Verdier. (n.d.). Retrieved January 29, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples40

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
ToolPupy

Pupy can execute Lazagne as well as Mimikatz using PowerShell.

T1003.004
LSA Secrets
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1003.005
Cached Domain Credentials
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1016
System Network Configuration Discovery
ToolPupy

Pupy has built in commands to identify a host’s IP address and find out other network configuration settings by viewing connected sessions.

T1021.001
Remote Desktop Protocol
ToolPupy

Pupy can enable/disable RDP connection and can start a remote desktop session using a browser web socket client.

T1033
System Owner/User Discovery
ToolPupy

Pupy can enumerate local information for Linux hosts and find currently logged on users for Windows hosts.

T1041
Exfiltration Over C2 Channel
ToolPupy

Pupy can send screenshots files, keylogger data, files, and recorded audio back to the C2 server.

T1046
Network Service Discovery
ToolPupy

Pupy has a built-in module for port scanning.

T1049
System Network Connections Discovery
ToolPupy

Pupy has a built-in utility command for netstat, can do net session through PowerView, and has an interactive shell which can be used to discover additional information.

T1055.001
Dynamic-link Library Injection
ToolPupy

Pupy can migrate into another process using reflective DLL injection.

T1056.001
Keylogging
ToolPupy

Pupy uses a keylogger to capture keystrokes it then sends back to the server after it is stopped.

T1057
Process Discovery
ToolPupy

Pupy can list the running processes and get the process ID and parent process’s ID.

T1059.001
PowerShell
ToolPupy

Pupy has a module for loading and executing PowerShell scripts.

T1059.006
Python
ToolPupy

Pupy can use an add on feature when creating payloads that allows you to create custom Python scripts (“scriptlets”) to perform tasks offline (without requiring a session) such as sandbox detection, adding persistence, etc.

T1071.001
Web Protocols
ToolPupy

Pupy can communicate over HTTP for C2.

T1082
System Information Discovery
ToolPupy

Pupy can grab a system’s information including the OS version, architecture, etc.

T1083
File and Directory Discovery
ToolPupy

Pupy can walk through directories and recursively search for strings in files.

T1087.001
Local Account
ToolPupy

Pupy uses PowerView and Pywerview to perform discovery commands such as net user, net group, net local group, etc.

T1105
Ingress Tool Transfer
ToolPupy

Pupy can upload and download to/from a victim machine.

T1113
Screen Capture
ToolPupy

Pupy can drop a mouse-logger that will take small screenshots around at each click and then send back to the server.

T1114.001
Local Email Collection
ToolPupy

Pupy can interact with a victim’s Outlook session and look through folders and emails.

T1123
Audio Capture
ToolPupy

Pupy can record sound with the microphone.

T1125
Video Capture
ToolPupy

Pupy can access a connected webcam and capture pictures.

T1134.001
Token Impersonation/Theft
ToolPupy

Pupy can obtain a list of SIDs and provide the option for selecting process tokens to impersonate.

T1135
Network Share Discovery
ToolPupy

Pupy can list local and remote shared drives and folders over SMB.

T1136.001
Local Account
ToolPupy

Pupy can user PowerView to execute “net user” commands and create local system accounts.

T1136.002
Domain Account
ToolPupy

Pupy can user PowerView to execute “net user” commands and create domain accounts.

T1497.001
System Checks
ToolPupy

Pupy has a module that checks a number of indicators on the system to determine if its running on a virtual machine.

T1543.002
Systemd Service
ToolPupy

Pupy can be used to establish persistence using a systemd service.

T1547.001
Registry Run Keys / Startup Folder
ToolPupy

Pupy adds itself to the startup folder or adds itself to the Registry key SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run for persistence.

T1548.002
Bypass User Account Control
ToolPupy

Pupy can bypass Windows UAC through either DLL hijacking, eventvwr, or appPaths.

T1550.003
Pass the Ticket
ToolPupy

Pupy can also perform pass-the-ticket.

T1552.001
Credentials In Files
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1555
Credentials from Password Stores
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1555.003
Credentials from Web Browsers
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolPupy

Pupy can sniff plaintext network credentials and use NBNS Spoofing to poison name services.

T1560.001
Archive via Utility
ToolPupy

Pupy can compress data with Zip before sending it over C2.

T1569.002
Service Execution
ToolPupy

Pupy uses PsExec to execute a payload or commands on a remote host.

T1573.002
Asymmetric Cryptography
ToolPupy

Pupy's default encryption for its C2 communication channel is SSL, but it also has transport options for RSA and AES.

T1685.005
Clear Windows Event Logs
ToolPupy

Pupy has a module to clear event logs with PowerShell.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.